* drop mbedtls 2.x support (which is end of life, and work on mbedtls 4
+
is much simplified by not having to take care of 2.x compat as well)
+
* PUSH_UPDATE: bugfix for the client side where split/continued messages
+
(due to large number of "route" statements) would not correctly handle
+
the full set of routes. Add unit test. (GH: [OpenVPN/openvpn#925](https://github.com/OpenVPN/openvpn/issues/925))
+
* new unit test module for mbuf handling
+
* deprecate --fast-io option (it got partially broken by the multisocket
+
implementation, and the benefits of the existing implementation did
+
not outweigh the extra code complexity to make it work again)
+
* change the ssl_ctx in struct tls_options to be a pointer - this is
+
a shared data structure between various contexts, but previously it
+
was shallow-copied, leading to needless CRL reloading - and when
+
working on implementing the new OpenSSL CRL API, to segfaults
+
(the existing code works, as these new APIs are not used yet).
+
+
For a list of all changes see the [git log](https://github.com/OpenVPN/openvpn/compare/v2.7_rc3...v2.7_rc4).
+
+
Highlights of 2.7 include:
+
* Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
+
* Improved Client support for DNS options
+
* Client implementations for Linux/BSD/macOS, included with the default install
+
* New client implementation for Windows, adding support for features like split DNS and DNSSEC
+
* Architectural improvements on Windows
+
* The `block-local` flag is now enforced with WFP filters
+
* Windows network adapters are now generated on demand
+
* Windows automatic service now runs as an unpriviledged user
+
* Support for server mode in win-dco driver
+
* Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
+
* Improved data channel
+
* Enforcement of AES-GCM usage limit
+
* Epoch data keys and packet format
+
* Support for new upstream DCO Linux kernel module
+
* This release supports the new `ovpn` DCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the [ovpn-backports project](https://github.com/OpenVPN/ovpn-backports).
+
* Client-side support for new `PUSH_UPDATE` control-channel message
+
* This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
+
* PUSH_UPDATE server support (minimal)
+
* New management interface commands `push-update-broad` and `push-update-cid` to send PUSH_UPDATE option updates.
+
* TLS 1.3 support with bleeding-edge mbedTLS versions
+
* Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
+
* Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
+
* "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
+
* COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
+
+
For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_rc4/Changes.rst)
For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
+
## OpenVPN 2.7_rc3 -- Released 28 November 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc3. This is the third release candidate for the feature release 2.7.0.